CVE Tools

Qemu

436 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Qemu, a product in the operating systems space. Use it to gauge the current risk picture and drill into individual advisories.

Qemu CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Qemu CVEs per month
MonthCVEs
2024-101
2024-112
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-072
2025-080
2025-091
2025-102
2025-110
2025-120
2026-010
2026-021
2026-030
2026-040
2026-051
2026-060
2026-070
2026-080
2026-090

Severity

How the 436 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical143%
  • High12529%
  • Medium25659%
  • Low419%

Latest CVEs

The 15 most recently published vulnerabilities affecting Qemu.

  1. BDU:2026-06263Уязвимость эмулятора аппаратного обеспечения QEMU, связанная с недостаточной проверкой вводимых данных, позволяющая нарушителю вызвать отказ в обслуживании6.5
  2. CVE-2025-14876Qemu-kvm: unbounded allocation in virtio-crypto5.5
  3. CVE-2025-12464Qemu-kvm: stack buffer overflow in e1000 device via short frames in loopback mode6.2
  4. CVE-2025-11234Qemu-kvm: vnc websocket handshake use-after-free7.5
  5. BDU:2025-11394Уязвимость функции qxl_set_mode эмулятора аппаратного обеспечения QEMU, позволяющая нарушителю вызвать отказ в обслуживании6.0
  6. CVE-2025-54566hw/pci/pcie_sriov.c in QEMU through 10.0.3 has a migration state inconsistency, a related issue to CVE-2024-26327.4.2
  7. CVE-2025-54567hw/pci/pcie_sriov.c in QEMU through 10.0.3 mishandles the VF Enable bit write mask, a related issue to CVE-2024-26327.4.2
  8. CVE-2024-7730Qemu-kvm: virtio-snd: heap buffer overflow in virtio_snd_pcm_in_cb()7.4
  9. CVE-2024-3447Qemu: sdhci: heap buffer overflow in sdhci_write_dataport()6.0
  10. CVE-2024-6519Qemu: scsi: lsi53c895a: use-after-free local privilege escalation vulnerability8.2
  11. CVE-2024-8612Qemu-kvm: information leak in virtio devices3.8
  12. CVE-2024-8354Qemu-kvm: usb: assertion failure in usb_ep_get()5.5
  13. CVE-2024-7409Qemu: denial of service via improper synchronization in qemu nbd server during socket closure7.5
  14. CVE-2024-6505Qemu-kvm: virtio-net: queue index out-of-bounds access in software rss6.8
  15. CVE-2024-4467Qemu-kvm: 'qemu-img info' leads to host file read/write7.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store